Businesses across Australia and New Zealand are moving quickly to adopt generative and agentic AI, but many still have little visibility over how the technology is being used inside their organisations.
The growing divide between AI adoption and effective oversight is creating what industry leaders describe as an “AI governance gap.”
When we surveyed 687 IT and security leaders, we found that nearly 73 per cent of enterprises have already deployed AI in some form.
However, 81.7 per cent admit they have either dealt with an AI-related security or cost incident or fully expect to experience one shortly.
More surprisingly, organisations with deeply integrated AI deployments are 40 per cent more likely to report an incident than those still in the exploratory stage.
This happens because AI adoption is outpacing the governance frameworks designed to manage it. The risk has moved beyond employees simply visiting web-based portals.
Today, software developers and knowledge workers are quietly running local command-line interfaces, background processes, and Model Context Protocol (MCP) servers natively on Apple Silicon.
Traditional network-based security tools, such as Cloud Access Security Brokers (CASBs), are completely blind to this activity. IT teams have visibility into the device, but almost none into what’s running on it. They cannot detect which local files, credentials, or source code repositories an AI agent is accessing.
Governed vs. Ungoverned AI
Often, executives will say yes to AI without realising how much unvetted “Shadow AI” is already operating in their environment. But attempting to ban AI outright is an ineffective strategy.
Saying no does not give the results you expect; it rarely makes a tool disappear. It simply drives the activity underground. Work always finds a way.
The choice for organisations is never a simple yes or no to AI. It is a choice between governed and ungoverned AI.
To safely harness this technology, organisations must establish active guardrails. It is not about monitoring employees or checking all their personal prompts. It is about technically defining what an AI agent is allowed to do on their behalf.
You need to ensure that an AI assistant cannot accidentally access a sensitive corporate database or share proprietary code with an unmanaged server.
This is why we launched AI Governance, a first-of-its-kind native control plane for Mac. It provides security teams with runtime visibility and OS-level policy enforcement.
By deploying tamper-resistant configurations via Apple’s Declarative Device Management, organisations can ensure policies are actively enforced at the device level.
Managing Autonomous Agents and Tokenomics
Looking two or three years ahead, managing AI agents will become as fundamental to IT as managing user accounts is today.
We are rapidly moving toward the autonomous enterprise where there could be more AI agents doing work than human employees.
These agents need managed identities, authenticated access, and strict security boundaries, just like any human worker.
Through our integration with Okta for AI Agents, we are giving AI agents short-lived, vaulted credentials. This ensures every action is authorised from the endpoint to the cloud.
This level of control also addresses another growing executive concern, known as “tokenomics”. While CISOs are focused on preventing data leakage, CFOs are increasingly focused on the rising costs of AI tokens.
Without visibility, it is impossible to assess whether the outcomes justify the expenditure. Proper governance brings security, scale, and cost management together into a single, collaborative policy.
Plan for disruption
Early in my career, a mentor shared a piece of advice that has always stuck with me: “Plan the work, work the plan, and plan for disruption.”
If you do not plan for that third part, you are not prepared. The world of AI is going to change rapidly, and organisations must have the flexibility to adapt.
The AI revolution is happening first on Mac, driven by developers and power users who prefer Apple Silicon. Apple builds incredibly secure, privacy-first hardware, and we are here to help businesses build on that foundation.
By embracing visibility and OS-level controls, Australian and New Zealand organisations can confidently secure the agentic future.

